CVE-2022-50926
WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without authentication.
Scoring
- Severity
- HIGH
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.10%
- CWE
- CWE-565
- Published
- 2026-01-13
- Last modified
- 2026-03-13
Affected products
- Wago WAGO 750-8212 PFC200
Weakness type
Related vulnerabilities
- CVE-2026-0257 — PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
- CVE-2023-45128 — CSRF Token Reuse Vulnerability in fiber
- CVE-2023-41084 — Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking
- CVE-2025-2395 — e-Excellence U-Office Force - Improper Authentication
- CVE-2014-125112 — Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution
- CVE-2023-32725 — Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.
- CVE-2024-9970 — NewType FlowMaster BPM Plus - Privilege Escalation
- CVE-2024-22186 — Electrolink FM/DAB/TV Transmitter Reliance on Cookies without Validation and Integrity Checking